insecure-source-code-management

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent as an offensive security testing guide, but its actual footprint is high-risk because it teaches an AI agent to probe for and recover sensitive source-control and config exposures, including secrets. There is no direct credential exfiltration to attacker-controlled endpoints and no installer payloads in the skill text, so this is not confirmed malware; however, it is a security/exploit-oriented skill with transitive skill-loading and optional third-party tool use, making it unsuitable for general-purpose agent deployment.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/yaklang%2Fhack-skills%2Finsecure-source-code-management%2F@c3575dfc003a81d1b16effcae05599b9f06d53f3dcf64758dcfc100753dd82b4
Security Audit — socket — insecure-source-code-management